Threats Tagged 'cve-2026-96890'
View all threats tagged with 'cve-2026-96890'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-96890'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-96890 is a Server-Side Request Forgery (SSRF) vulnerability in GitHub Enterprise Server that allowed authenticated repository contributors to make the server issue requests to attacker-controlled internal hosts. This could be chained to achieve remote code execution on the appliance. The issue stemmed from the secret scanning validator for GCP service account credentials trusting token endpoints embedded in committed credentials without restricting destinations. It affected GitHub Enterprise Server versions 3.20.0 through before 3.20.9, 3.21.0 through before 3.21.7, and 3.22.0 through before 3.22.2. The vulnerability was fixed in versions 3.20.9, 3.21.7, and 3.22.2. Exploitation required an authenticated user with push permissions on a repository with GitHub Advanced Security and secret scanning validity checks enabled, which is a non-default configuration. Join the discussion | CVE Database V5 | 10/06/2026, 18:56:46 UTC Added: 10/06/2026, 19:04:17 UTC |
Showing 1 to 1 of 1 result